CISA KEV · catalog date Mar 3, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2017-12238
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent…
Exploited in the wild (CISA KEV since Mar 3, 2022). NVD reports CVSS 3.1 6.5. EPSS estimates 2.0% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition. The vulnerability is due to a memory management issue in the affected software. An attacker could exploit this vulnerability by creating a large number of VPLS-generated MAC entries in the MAC address table of an affected device. A successful exploit could allow the attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a DoS condition. This vulnerability affects Cisco Catalyst 6800 Series Switches that are running a vulnerable release of Cisco IOS Software and have a Cisco C6800-16P10G or C6800-16P10G-XL line card in use with Supervisor Engine 6T. To be vulnerable, the device must also be configured with VPLS and the C6800-16P10G or C6800-16P10G-XL line card needs to be the core-facing MPLS interfaces. Cisco Bug IDs: CSCva61927.
- State
- PUBLISHED
- Published
- Sep 28, 2017
- Updated
- Jan 12, 2026
- Evidence coverage
- 92%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCAciscoOriginal evidence ↗
Record text: A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition. The vulnerability is due to a memory management issue in the affected software. An attacker could exploit this vulnerability by creating a large number of VPLS-generated MAC entries in the MAC address table of an affected device. A successful exploit could allow the attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a DoS condition. This vulnerability affects Cisco Catalyst 6800 Series Switches that are running a vulnerable release of Cisco IOS Software and have a Cisco C6800-16P10G or C6800-16P10G-XL line card in use with Supervisor Engine 6T. To be vulnerable, the device must also be configured with VPLS and the C6800-16P10G or C6800-16P10G-XL line card needs to be the core-facing MPLS interfaces. Cisco Bug IDs: CSCva61927.
Inspect raw assertion
- Field
container- Value
- A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition. The vulnerability is due to a memory management issue in the affected software. An attacker could exploit this vulnerability by creating a large number of VPLS-generated MAC entries in the MAC address table of an affected device. A successful exploit could allow the attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a DoS condition. This vulnerability affects Cisco Catalyst 6800 Series Switches that are running a vulnerable release of Cisco IOS Software and have a Cisco C6800-16P10G or C6800-16P10G-XL line card in use with Supervisor Engine 6T. To be vulnerable, the device must also be configured with VPLS and the C6800-16P10G or C6800-16P10G-XL line card needs to be the core-facing MPLS interfaces. Cisco Bug IDs: CSCva61927.
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 2.03% probability · 79.65th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.020340000000; percentile 0.796510000000
FIRST EPSS · score date Aug 27, 2026 · 79.7th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition. The vulnerability is due to a memory management issue in the affected software. An attacker could exploit this vulnerability by creating a large number of VPLS-generated MAC entries in the MAC address table of an affected device. A successful exploit could allow the attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a DoS condition. This vulnerability affects Cisco Catalyst 6800 Series Switches that are running a vulnerable release of Cisco IOS Software and have a Cisco C6800-16P10G or C6800-16P10G-XL line card in use with Supervisor Engine 6T. To be vulnerable, the device must also be configured with VPLS and the C6800-16P10G or C6800-16P10G-XL line card needs to be the core-facing MPLS interfaces. Cisco Bug IDs: CSCva61927.
Inspect raw assertion
- Field
container- Value
- A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition. The vulnerability is due to a memory management issue in the affected software. An attacker could exploit this vulnerability by creating a large number of VPLS-generated MAC entries in the MAC address table of an affected device. A successful exploit could allow the attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a DoS condition. This vulnerability affects Cisco Catalyst 6800 Series Switches that are running a vulnerable release of Cisco IOS Software and have a Cisco C6800-16P10G or C6800-16P10G-XL line card in use with Supervisor Engine 6T. To be vulnerable, the device must also be configured with VPLS and the C6800-16P10G or C6800-16P10G-XL line card needs to be the core-facing MPLS interfaces. Cisco Bug IDs: CSCva61927.
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability
2.03% probability · 79.65th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.020340000000; percentile 0.796510000000
Applicability
Cited product scope
Grouped from 2 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
21 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "Cisco IOS"}]product-6952822a54407c0c4651a44d8d0c79ea63da2cc4143d93d08c64e87e713e3c69Linked exactInspect raw assertion
cpe:2.3:h:cisco:c6800-16p10g:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1d782feb-ff9a-4f41-95ba-88c239656f7d
product-87ebfdd885ed138d67813ec1a47e08c93629191d84896218cea2f232d6494b52Linked exactInspect raw assertion
cpe:2.3:h:cisco:c6800-16p10g-xl:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f508c81e-d31b-44ba-82c8-feda00324b8b
product-7f1dbeed12f46adfd6122648af88e86e09bc4082558ead3025116589484dc184Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_6000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
38280588-3ce2-4797-a56a-00256e634c62
product-7a4529d3837344004dac3c72878edd6d1eb062c32e96e446ce42853802fec57dLinked exactInspect raw assertions
cpe:2.3:h:cisco:catalyst_6000_ws-svc-nam-1:3.1\(1a\):*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0bf0bbc8-04bd-4867-b188-35461e50ff16
cpe:2.3:h:cisco:catalyst_6000_ws-svc-nam-1:2.2\(1a\):*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1a2af1c7-23eb-4c13-ac71-4fa7e78e8ed7
product-bcaeb1fbd703df4116e1411e2418135c6e975498b1db87680b73318062f12598Linked exactInspect raw assertions
cpe:2.3:h:cisco:catalyst_6000_ws-svc-nam-2:2.2\(1a\):*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a2c1e3f7-d48e-4af1-8205-33eb71e09e09
cpe:2.3:h:cisco:catalyst_6000_ws-svc-nam-2:3.1\(1a\):*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c959c93d-d58c-4ab5-9058-0cf257c68f72
product-7f4aab602b8e9530ef49a2396d55e3b86413074b9c78a9f078bd1fbfea5db348Linked exactInspect raw assertions
cpe:2.3:h:cisco:catalyst_6000_ws-x6380-nam:3.1\(1a\):*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e2df345d-ad8a-4de6-8136-6ef7b011e4b1
cpe:2.3:h:cisco:catalyst_6000_ws-x6380-nam:2.1\(2\):*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4fdb5eac-e41d-4a15-b059-45b4be4813ec
product-1b675d4b39eb7441691fd69d6cc2f501938520972d12656d57ffc8bfb33a69b7Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_6500:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
defbfa86-64f2-4cb0-99e1-faefca690ff8
product-197658cb7d58240b03eff671f2a9502f34b55db8165ad1b57a253471eed85ba9Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_6500-e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
15b48565-92c7-4ae1-ae3a-6ff7dd010745
product-ce4c460cc425a36c7f8b8864928d1199e90be6376eb51a1deb762a2413c1fe10Linked exactInspect raw assertions
cpe:2.3:h:cisco:catalyst_6500_ws-svc-nam-1:3.1\(1a\):*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e6bed8bd-79d2-4dd9-a895-66a8c9349f62
cpe:2.3:h:cisco:catalyst_6500_ws-svc-nam-1:2.2\(1a\):*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ec58b690-8d30-4a04-82aa-a827f87dee02
product-d0c7950d992e052c2bf23c8736ee2544093a1ddef59ded4b7263d8447b1a873aLinked exactInspect raw assertions
cpe:2.3:h:cisco:catalyst_6500_ws-svc-nam-2:2.2\(1a\):*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
41491d13-a3f9-464a-a84b-a58320838cbd
cpe:2.3:h:cisco:catalyst_6500_ws-svc-nam-2:3.1\(1a\):*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9e0747c3-2712-4fa9-92e3-260b3cf080dc
product-9d5e1e70551ef0f2f76c8bf3a4b3aaee575b1e7039f1ddf14abba0c29099e130Linked exactInspect raw assertions
cpe:2.3:h:cisco:catalyst_6500_ws-x6380-nam:3.1\(1a\):*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dd4d3f34-a1b3-4469-bf21-666fdae9198b
cpe:2.3:h:cisco:catalyst_6500_ws-x6380-nam:2.1\(2\):*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cff4cbff-56c4-4411-9f12-2506c3dd563e
product-a715acb0b34d5b5c26a59f7943205dbf10520a17155232e2d1425271b68d2f46Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_6503-e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f202892e-2e58-4d77-b983-38afa51cdbc6
product-e06128359ff90247875eafd4e6aab6d03b1675dd483fc2b7594e48128495f3e5Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_6504-e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7f57df3e-4069-4ef0-917e-84cddfcebeef
product-c3d343ba4c882bc9515f0bc30b87891d41c725bde9c94629d11965c6d010ef7dLinked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_6506-e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0be25114-abbc-47a0-9c20-e8d40d721313
product-a56ab3dbd9557f78755ddae44020efc6c3b108cf158e3194122106e97ec73a40Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_6509-e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fadd5f49-2817-40ec-861c-c922825708bd
product-d7a502147bfbfe870e7704cb31cc778c28a297b725d7e7e0f0e0ac056b6c2d07Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_6509-neb-a:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e628f9c4-98c6-4a95-af81-f1e6a56e8648
product-60c61fd5c908cf0f6384f17f7d754645caa9fa2131d9289f5d1247eb40cc96d2Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_6509-v-e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4aff899c-1eb3-46d8-9003-ea36a68c90b3
product-750bf716665435ffbee7c5b22ed845a2e50b53a7e8e91702a5ef993012e1441cLinked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_6513:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e6463491-f63e-44cb-a1d4-c029be7d3d3d
product-1f8664fcc183ed1fcc80ed7d9fcd4a66d23109ead12d0dee52cea26eb4b05636Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_6513-e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d8668d34-096b-4fc3-b9b1-0ecfd6265778
product-5972f4392170d0d1b4e75a10eb3b383835ead601c8d9b09329525407a4e1471aLinked exactInspect raw assertion
cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 15.0; through including 15.4
- Match ID
2c8accbc-19e5-4960-84bf-bd6ebae0ac39
Affected-product evidence
Accepted scope and product mapping
1 canonical links · 1 source-reported links
vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-5972f4392170d0d1b4e75a10eb3b383835ead601c8d9b09329525407a4e1471a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
695936f0-8301-4db3-a47b-88b2b4160c76Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c62c417e-a6c0-4e7a-b999-74fae5152960Assessments
CVSS by origin
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HAV:A/AC:L/Au:N/C:N/I:N/A:PCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Validation
- Valid match
- Recomputed
- 6.5
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.